
drupalgeddon2-cve-lab
Intentionally vulnerable Drupal 7.57 lab for reproducing CVE-2018-7600 (Drupalgeddon2) in a Docker container, with an installer script and PHP…

Intentionally vulnerable Drupal 7.57 lab for reproducing CVE-2018-7600 (Drupalgeddon2) in a Docker container, with an installer script and PHP…

PoC exploit for Adminer < 5.4.3 unauthenticated RCE via MSSQL PDO DSN injection, including Docker lab and negative test.

Proof-of-concept exploit for CVE-2026-2058, a SQL injection in CloudClassroom PHP Project, with automated database enumeration and data extraction.

PoC exploit for CVE-2026-17543: SQL injection in PHP ext/pgsql via backslash breakout, with data exfiltration and admin privilege-escalation payloads…

Exploit PoC and root-cause analysis for a critical unauthenticated PHP object injection in WordPress Database for Contact Form 7, leading to RCE via…

PoC exploit for CVE-2024-1813: PHP object injection in Simple Job Board WordPress plugin, achieving unauthenticated RCE via gadget chain. Includes…

Proof-of-concept exploit for CVE-2022-31630, an out-of-bounds read vulnerability in PHP's GD extension. Demonstrates crash and memory disclosure in…

A deliberately vulnerable web application for learning web application security.

Docker-based lab environment for WordPress <= 4.6 remote code execution via PHPMailer (CVE-2016-10033), including PoC, webshell upload, and reverse…

Roundcube 1.0.0 <= 1.2.2 Remote Code Execution exploit and vulnerable container

CVE-2024-4577 PHP CGI Argument Injection - Detection Lab with Vagrant VMs and Wazuh SIEM rules

Docker-based lab environment for studying CVE-2024-4577, a PHP-CGI argument injection vulnerability, with Apache and PHP 8.1.2 in CGI mode.

Lab environment and exploit script for CVE-2020-7246, a PHP code injection vulnerability in qdPM 9.1. Includes Docker setup and Python2-based…

Vulnerable test environment for CVE-2020-13756 (Sabberworm PHP CSS Parser RCE)

Docker-based lab environment and proof-of-concept scripts for exploiting CVE-2020-10560, an arbitrary file read vulnerability in OSSN. Includes PHP…

Docker-based lab environment to reproduce and exploit CVE-2024-56145, a PHP register_argc_argv RCE vulnerability in CraftCMS, with step-by-step setup…

CVE-2025-61246: SQL Injection vulnerability PoC in Online Shopping System PHP

Docker-based lab environment demonstrating CVE-2018-19518 RCE exploit via PHP IMAP extension, with step-by-step usage and WAF integration for…